2024 CVE Vulnerabilities

39,217 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-36333HIGH7.8A DLL hijacking vulnerability in the AMD Cleanup Utility could allow an attacker to achieve privilege escalation potenti...
CVE-2024-36323HIGH8.8Improper isolation of VCN-JPEG HW register space could allow a malicious Guest Virtual Machine (VM) or a process to perf...
CVE-2024-21950LOW1.8An out of bounds read in the remote management firmware could allow a privileged attacker read a limited section of memo...
CVE-2024-36332MEDIUM6.8Improper isolation of GPU HW register space could allow a privileged attacker in malicious Guest Virtual Machine (VM) to...
CVE-2024-21962HIGH8.6Improper Input Validation in the AMD RAID driver could allow an attacker to point to an arbitrary memory location potent...
CVE-2024-36345MEDIUM4.6Improper input validation in the AMD OverDrive (AOD) System Management Mode (SMM) module could allow a privileged attack...
CVE-2024-48519MEDIUM6.2Buffer Overflow vulnerability in Ardupilot rover commit v.c56439b045162058df0ff136afea3081fcd06d38 allows a local attack...
CVE-2024-55045HIGH7.3Firmament-Autopilot FMT-Firmware commit de5aec was discovered to contain a buffer overflow via the task_mavobc_entry fun...
CVE-2024-51395MEDIUM6.2Buffer Overflow vulnerability in Ardupiot Copter Latest commit 92693e023793133e49a035daf37c14433e484778 allows a local a...
CVE-2024-51394MEDIUM5.5Buffer Overflow vulnerability in Ardupiot Copter Latest commit 92693e023793133e49a035daf37c14433e484778 allows a local a...
CVE-2024-47091HIGH7.8Privilege escalation in the mk_mysql agent plugin on Windows in Checkmk <2.4.0p29, <2.3.0p47, and 2.2.0 (EOL) allows a l...
CVE-2024-36315MEDIUM5.7Improper enforcement of the LFENCE serialization property may allow an attacker to bypass speculation barriers and poten...
CVE-2024-54017MEDIUM6.9A vulnerability has been identified in SIPROTEC 5 6MD84 (CP300) (All versions < V11.0), SIPROTEC 5 6MD85 (CP200) (All ve...
CVE-2024-0391MEDIUM4.3The check user account lock states feature within the email OTP flow fails to validate user input, allowing an attacker ...
CVE-2024-53326HIGH7.3LINQPad before 5.52.01 Pro edition is vulnerable to Unsafe Deserialization in LINQPad.AutoRefManager::PopulateFromCache(...
CVE-2024-51092CRITICAL9.1LibreNMS before 24.10.0 allows a remote attacker to execute arbitrary code via OS command injection involving AboutContr...
CVE-2024-46508HIGH7.5yeti-platform yeti before 2.1.12 allows attackers to generate valid JWT tokens is the secret is not changed (by setting ...
CVE-2024-46507HIGH7.3A SSTI (server side template injection) vulnerability in the custom template export function in yeti-platform yeti befor...
CVE-2024-45257HIGH7.3A Command Injection issue in the payload build page in BYOB (Build Your Own Botnet) 2.0 allows attackers to execute arbi...
CVE-2024-33724MEDIUM5.4SOPlanning 1.52.00 is vulnerable to Cross Site Scripting (XSS) via the groupe_id parameter to process/groupe_save.php.
CVE-2024-33722MEDIUM6.3SOPlanning 1.52.00 is vulnerable to SQL Injection by an authenticated user via projets.php with statut[].
CVE-2024-33288HIGH7.3Prison Management System Using PHP v1.0 was discovered to contain a SQL injection vulnerability via the username on the ...
CVE-2024-30167MEDIUM6.3/cgi-bin/time.cgi in Atlona AT-OME-MS42 Matrix Switcher 1.1.2 allow remote authenticated users to execute arbitrary comm...
CVE-2024-27686HIGH7.5Mikrotik RouterOS (x86) 6.40.5 through 6.49.10 (fixed in 7) allows a remote attacker to cause a denial of service (devic...
CVE-2024-43384HIGH8A low privileged remote attacker can gain the root password due to improper removal of sensitive information before stor...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now